WG385 IIS6 - All web server documentation, sample code, example applications, and tutorials must be removed. - 'Inetpub\Iissamples'

Information

Web server documentation, sample code, example applications, and tutorials may be an exploitable threat to a web server. A production web server may only contain components that are operationally necessary (e.g., compiled code, scripts, web-content, etc.). Delete all directories containing samples and any scripts used to execute the samples.

Solution

Remove sample code and documentation from the web server.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|I, Rule-ID|SV-38330r1_rule, STIG-ID|WG385_IIS6, Vuln-ID|V-13621

Plugin: Windows

Control ID: a26b4c739fe505b713a7dfe9271a6a25b0e863c5e541b7158e264874d84c7fc2